This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Beacon Technologies is seeking a Security and Application Security Engineer. The Security and Application Security Engineer position is responsible for a combined effort of general infrastructure cyber security as well position is focused on performing application security testing, design, and working in partnership with development teams throughout the organization. The scope of responsibility also includes but is not limited to static and dynamic application security testing, penetration testing, maturing the software development life cycle, and API security testing. Successful candidates will be able to review application code and development environments for security concerns and best practices, making recommendations and assisting development teams in implementing recommendations from those assessments. This position works closely and in partnership with the various teams and business units throughout the organization. The scope of responsibility includes but is not limited to the following networking technologies: Vulnerability Management, Threat Analysis, Threat hunting, Security incident Management, general security hygiene, Internet, firewalls/DMZ, IP network and communications rooms (equipment, software/protocols, and cabling), monitoring, test systems/platforms, overall data security and encryption. The position also entails cloud-based technologies such as Amazon Web Services, and colocation solutions used in conjunction with on-premises data centers. The position will also be responsible for performing periodic compliance tasks as required, and/or assisting to maintain desired industry certifications for the organization. *Please note, this role is a 1-year long contracted position.
Job Responsibility:
Operate as a liaison between the Security Team and the Development Teams
Preserve PCI and SOX Security Certification programs with a primary focus on ensuring compliance with the appropriate industry standards and security controls
Supporting incident response and architecture review whenever applications security expertise is needed
Integrating threat modeling practices into the SDLC
Work with other staff to perform periodic scans and evaluation of system security including areas such as patch management, penetration testing, vulnerability assessments, and other types of InfoSec-related tasks
Assist in identifying and communicating security exposures, information security incidents or non-compliance situations to IT management or the CISO as appropriate. Duties may also include collecting and documenting cyber security and incident response event data as necessary.
Requirements:
Minimum of five years of Information Security experience with at least two years of application-level security
Strong communication skills: ability to convey and document security guidelines, requirements, and coding best practices
Familiarity with Security Best Practices in common coding languages
Application Penetration Testing / API Security Testing
Software Development Life Cycle Design and Implementation
Static and Dynamic Application Testing Tools and Methods
Container and orchestration security (Kubernetes, Docker, Octopus, GitHub, etc.)
Familiarity with Application Security Testing Frameworks such as OWASP
Strong logical and analytical thinker
exceptional skills in security systems solutions
Ability to work both independently and as part of a local and/or remote technology team
Attention to detail and demonstrated history of using careful approaches to tasks being performed
Can anticipate risks and mitigate issues in the moment
Strong verbal and written communication skills
Basic networking skill set is required along with experience in securing wide area networks and a hybrid approach for on-premises/cloud/colocation technology environments across multiple locations. Demonstrated expertise of networking knowledge including a thorough understanding of the OSI model
Compliance – PCI-DSS, PCI-CP, SOX. PCI requirements and reporting, NIST regulatory and compliance environments, and demonstrated broad range of skills with security publications, privacy data identification/handing, security engineering concepts, C&A procedures and policy development
Experience in securing off-premises network resources, including colocation sites, remote data centers, Amazon Web Services and/or Azure. Need to have a strong background in Cloud Cyber Security
Basic knowledge and working experience with Linux, Windows, VMware, and other operating systems and applications typically found in an enterprise corporate environment having remote locations
Kali Linux toolsets, and application-level toolsets such as Postman and Burp
Threat Intelligence research
Risk management methodologies
Threat Hunting
Simulated threat skillsets (Red / blue teaming)
Malware analysis
Bachelor’s degree in information technology or related field is preferred. Preferences will be given for having generally accepted Industry InfoSec certifications such as CISSP, CISM, CEH, etc.
Nice to have:
Bachelor’s degree in information technology or related field
generally accepted Industry InfoSec certifications such as CISSP, CISM, CEH, etc.
What we offer:
Career advancement opportunities
extensive training
excellent benefits including paying for health and dental premiums for salaried employees.
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.